bce470
#!/bin/bash
bce470
# This script delivers current documentation/configs and assures it has the intended
bce470
# settings for a particular branch/release.
bce470
# For questions reach to Jindrich Novy <jnovy@redhat.com>
bce470
bce470
ensure() {
bce470
  if grep ^$2[[:blank:]].*= $1 > /dev/null
bce470
  then
bce470
    sed -i "s;^$2[[:blank:]]=.*;$2 = $3;" $1
bce470
  else
bce470
    if grep ^\#.*$2[[:blank:]].*= $1 > /dev/null
bce470
    then
bce470
      sed -i "/^#.*$2[[:blank:]].*=/a \
bce470
$2 = $3" $1
bce470
    else
bce470
      echo "$2 = \"$3\"" >> $1
bce470
    fi
bce470
  fi
bce470
}
bce470
bce470
#./pyxis.sh
bce470
#./update-vendored.sh
bce470
spectool -f -g containers-common.spec
bce470
ensure storage.conf    driver                        \"overlay\"
bce470
ensure storage.conf    mountopt                      \"nodev,metacopy=on\"
bce470
if pwd | grep rhel-8 > /dev/null
bce470
then
38a67a
ensure registries.conf unqualified-search-registries [\"registry.access.redhat.com\",\ \"registry.redhat.io\",\ \"docker.io\"]
bce470
ensure registries.conf short-name-mode               \"permissive\"
bce470
ensure containers.conf runtime                       \"runc\"
ae5259
ensure containers.conf events_logger                 \"file\"
ae5259
ensure containers.conf log_driver                    \"k8s-file\"
ae5259
ensure containers.conf network_backend               \"cni\"
0a8224
if ! grep \"NET_RAW\" containers.conf > /dev/null
0a8224
then
0a8224
  sed -i '/^default_capabilities/a \
0a8224
  "NET_RAW",' containers.conf
0a8224
fi
bce470
else
38a67a
ensure registries.conf unqualified-search-registries [\"registry.access.redhat.com\",\ \"registry.redhat.io\",\ \"docker.io\"]
bce470
ensure registries.conf short-name-mode               \"enforcing\"
bce470
ensure containers.conf runtime                       \"crun\"
bce470
fi
bce470
[ `grep "keyctl" seccomp.json | wc -l` == 0 ] && sed -i '/\"kill\",/i \
bce470
				"keyctl",' seccomp.json
bce470
sed -i '/\"socketcall\",/i \
bce470
				"socket",' seccomp.json